Sharing personal data with other organisations is commonplace in business, but always bear in mind that it gives rise to different types of relationships under UK data protection law with varying implications. It’s key to understand which of these relationships relates to your business and the consequence of each. These are the main types of data sharing relationships:
Independent Controller
The UK GDPR defines a controller as an entity which “determines the purposes and means of the processing of personal data”. So, where controllers share personal data and use the data for distinct and different purposes this will result in an independent controller relationship. Whilst it is not mandatory to regulate such data sharing in a written contract it is advisable, as it enables the discloser to require that the recipient adopts adequate security measures and to expressly restrict the purposes for which the recipient can use the data, for example by prohibiting it from using the data for marketing purposes.
Joint Controller
A joint controller relationship arises where two or more parties jointly determine the purposes and means of the data processing. The determination of a joint controller relationship needs to be based on a careful assessment of the facts, but it will typically arise where businesses share personal data in a joint venture. Article 26 of the UK GDPR requires that joint controllers enter an arrangement under which they decide who will carry out which controller obligation. In practice, this is generally included in a written contract which sets out the parties’ respective responsibilities for matters such as providing information to data subjects and dealing with data subject access rights.
Controller and Processor
A processor processes personal data “on behalf of the controller”. So, where one party determines the purposes and essential means of the processing and another party processes personal data only on its instructions this will give rise to a controller and processor relationship. Article 28 of the UK GDPR mandates specific requirements which need to be agreed between such parties such as the right of the controller to undertake compliance audits and an obligation on the processor to ensure that its personnel have committed themselves to confidentiality.
Whilst this gives you an overview of different data sharing relationships, the devil is in the detail. Due to a series of court decisions over the last decade and the increasing ways in which personal data is being shared, understanding exactly who is responsible for determining the purpose and means of the processing in any given scenario has become increasingly complicated.
As a starter, here are some questions to ask before sharing personal data with another organisation:
- Which party is determining the purpose and means of the data processing?
- Is the data being processed for the parties’ jointly determined purposes or will they be processing the data for distinct and different purposes?
- Is one party processing the data solely on the instruction of, and for purposes determined by, the other?
- What types of personal data are being processed (in particular, does it include special categories of personal data as defined in Article 9 of the UK GDPR)?
- What is the lawful basis of the data sharing for the purposes of Article 6 and (in the case of special categories of personal data) Article 9?
- In the case of international transfers, is there a requirement for appropriate safeguards as set out in Article 46?
For guidance on data sharing and the appropriate protection for your business please do not hesitate to get in touch with Data Privacy and Commercial specialist Andrew Elishahoff.